Cross Site Scripting Vulnerability in Intelbras RF 301K
CVE-2025-4996

4.8MEDIUM

Key Information:

Vendor

Intelbras

Status
Vendor
CVE Published:
20 May 2025

What is CVE-2025-4996?

A vulnerability exists in the Intelbras RF 301K version 1.1.5, related to improper processing of the Add Static IP component, which enables an attacker to execute a cross site scripting (XSS) attack. By manipulating the argument 'Description', an attacker may be able to inject arbitrary scripts, which can be executed in the context of a user’s browser. This vulnerability may allow attackers to potentially steal session cookies, credentials, or perform other malicious actions. This issue has been publicly disclosed, making it crucial for affected users to implement remediation measures promptly.

Affected Version(s)

RF 301K 1.1.5

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Havook (VulDB User)
.